SIM swap attacks use a phone number to unlock accounts through “forgot password, text me a code.” There’s an older, lower-tech version of the same underlying problem that doesn’t need your phone at all: enough of your identifying information (name, birthdate, Social Security number, previous addresses — all things a data broker profile or an old breach dump can supply) to open credit in your name directly. Both attacks share a root cause. They don’t share a fix.
Want the technical reference sheet for this stuff too? Subscribe and get the Security Command Reference free — plus one new deep-dive article a week, no daily spam.
Why This Isn’t the Same Problem as Someone Draining an Existing Account
Most fraud people picture is someone getting into an account you already have — a stolen password, a compromised login. Identity theft in the credit-freeze sense is different and in some ways worse: an attacker opens brand new credit in your name that you never had, using nothing but your identifying information, and you often don’t find out until a collections call arrives or you’re denied a loan for debt you never took on. The account never had a password for someone to steal, because you never opened it — the attacker did, using your identity as the raw material.
Credit Freeze vs. Fraud Alert: Two Different Tools
A credit freeze blocks new creditors from accessing your credit report at all, at each of the three bureaus (Equifax, Experian, TransUnion) individually. No access to the report means no new credit account can be opened in your name, because legitimate lenders won’t extend credit without pulling a report first. This is the strongest available protection, it’s free by federal law, and the actual mechanics are simple: freeze at all three bureaus, get a PIN or password for each, and temporarily lift the freeze (a “thaw,” also free) only when you’re the one applying for credit. The friction of managing three separate thaws is real but small compared to what it prevents.
A fraud alert is weaker and easier: it requires creditors to take extra verification steps before opening an account, rather than blocking access outright. An initial fraud alert lasts one year and is free; an extended alert (for confirmed identity theft victims) lasts seven years. A fraud alert placed at one bureau is supposed to notify the other two automatically, though in practice this doesn’t always work reliably — worth confirming directly at all three rather than assuming the automatic notification went through.
The freeze is the stronger tool and the one worth defaulting to for anyone not actively shopping for credit. The alert is the lighter-weight option for someone who wants some protection without managing three separate freeze/thaw relationships, or as a required step specifically after confirmed fraud, alongside a freeze rather than instead of one.
What Actually Happens After a Freeze Is In Place
- Existing accounts are unaffected. A freeze blocks new credit report pulls, not your existing cards or loans — you can keep using accounts you already have normally.
- You’ll need to thaw before any legitimate credit application — a new card, a car loan, an apartment application that runs a credit check, sometimes even certain employment background checks. Most bureaus support a temporary thaw (a specific window of hours or days) rather than requiring a full unfreeze, which limits the exposure window to exactly when you need it.
- Kids can and should have freezes too. Because children have no credit history, a fraudulently opened account in a child’s name can go completely undetected for years — often not discovered until they apply for their first real credit as an adult and find a decade of fraudulent activity already on file. All three bureaus support minor freezes; it requires more paperwork than an adult freeze but is worth doing well before it’s needed.
What I Actually Have in Place
Freezes at all three bureaus, set up years ago and left in place indefinitely rather than something I only think about when applying for credit. When I do need a thaw, I do it for the shortest available window rather than leaving it open longer than the specific application requires, and I confirm the freeze is back in place afterward rather than assuming the temporary thaw expired correctly on its own.
What I got wrong initially: I set freezes at Equifax and Experian when I first did this and assumed that covered it, having forgotten TransUnion existed as a separate bureau requiring its own freeze — an assumption I only caught because a specific lender pulled from TransUnion during an application and the absence of a freeze there became obvious in the moment rather than in advance. Nothing fraudulent had happened by the time I caught it, but the gap existed for longer than it should have simply because I’d mentally filed “credit bureaus” as a two-item list instead of three. It’s worth explicitly checking that all three, by name, actually have an active freeze — not just assuming the process is done because you did it once.
Common Mistakes
Freezing only one or two bureaus. Any bureau without an active freeze is a functioning door for a fraudulent application, regardless of how well-protected the other two are.
Treating a fraud alert as equivalent protection to a freeze. It requires extra verification, not a hard block — meaningfully weaker, especially against a patient or well-informed attacker.
Never freezing a minor’s credit because “they don’t have any.” That’s exactly why it’s vulnerable — no existing activity means no one is watching for anything unusual.